Oficla

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 660
First Seen: September 28, 2010
Last Seen: May 29, 2023
OS(es) Affected: Windows

Oficla is a harmful Trojan that attempts to install rogue security software into the computers it infects. Oficla aka Win32 Oficla, propagates via unsolicited e-mails with alarming subject titles such as "Facebook Password Reset Confirmation! Important Message". The said e-mails come with infected attachments that users are prompted to open for different reasons depending on each e-mail. On opening the attachment, Oficla will be executed then it will modify system settings and inject malicious code into running processes. Oficla may also install rogueware that will attempt to trick users into purchasing its non-existent "full" version.

Aliases

15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Sophos Mal/Hrup-A
eTrust-Vet Win32/Lipler.B!packed
Comodo TrojWare.Win32.Trojan.hrup.~GEN
Ikarus Trojan.Win32.Koobface
Sophos Mal/TinyDL-T
AntiVir BDS/Backdoor.Gen
DrWeb Trojan.DownLoader.origin
BitDefender Gen:Trojan.Heur.GZ.amGfb0EWYVj
ClamAV Worm.Koobface-316
Symantec Suspicious.MH690.A
NOD32 a variant of Win32/TrojanProxy.Small.NEB
McAfee New Malware.ai
CAT-QuickHeal Win32.Backdoor.Phdet.gen!A.3
Ikarus Trojan.Agent.Winlogon
a-squared Trojan.Agent.Winlogon!IK

SpyHunter Detects & Remove Oficla

File System Details

Oficla may create the following file(s):
# File Name MD5 Detections
1. svcnost.exe c59165f6be19fd6dd110e460d2cc086e 64
2. eepic.exe 13077948e94deea485534ad488fe6706 53
3. JUGAR Spanish.exe 78a3099a4cb54b4642794f2796dc9a1f 38
4. svcnost.exe e4996a8539e54f606e348e49b8e8c90c 35
5. svcnost.exe 727498a42f3b0368f079bf04969056d1 27
6. svcnost.exe d64889cb2879ceb4381bbf82d4df4113 22
7. M3SRCHMN.EXE 3fc62c7ee88d9cd09a381e10c630f04a 19
8. svcnost.exe 63c5410e8ffb7f29c88559947484c06c 16
9. svcnost.exe fd22114723f2856edfeaefa0f60e89c0 16
10. svcnost.exe 85e4a899602946939fc354c25e8a0669 15
11. svcnost.exe 81e71dc98adc6069d66672b88a6ff005 14
12. svcnost.exe 33c2482dc349e22d4d0e2f6ec6e8630e 12
13. svcnost.exe 2d20aec4f82c8d5f9e353c7cf451967a 9
14. svcnost.exe 85edf2df34fad6da18ad07967d2f6e20 8
15. svcnost.exe 05a244ba7b5c10a033a8fa78246b1b02 7
16. svcnost.exe 4733df448107ba795a51c76cec3e12b9 7
17. webserver.exe b88dcea9c4608001ceb296a2bc03c034 6
18. svcnost.exe bfeb8252ec5479c4e210a2e4fa29bffc 3
19. winlogon.exe 97da1545decf6c0c4e9ff90d40f18730 3
20. svcnost.exe 88a71d01bad7fd16c565a1fcf8ae5d67 2
21. svcnost.exe af1ebd8decd0498680198e649d64883d 2
22. CaptureWiz.exe 203519c12c488c051076eec0c2b97b5b 2
23. svcnost.exe 4b0e2edca081b19e7600ef581c718198 1
24. svcnost.exe df6b582421891247e54a5e147b4fe4fa 1
25. svcnost.exe 40158a5d0b76d19561ad814292e253d4 1
More files

Related Posts

Trending

Most Viewed

Loading...